tuta.com — 87/100 (Low privacy risk)
Last analyzed
Tutao GmbH · tuta.com
Report details
Low privacy riskTuta is a highly privacy-friendly encrypted email provider that stores all user data end-to-end encrypted in Germany, collects minimal metadata, uses no cookies, and shares data with third parties only for payment processing or under court order.
Tutao GmbH (Tuta) demonstrates strong privacy practices centered on end-to-end encryption and data minimization. All user content is encrypted so that even Tuta cannot access it. Only essential metadata (email addresses, timestamps) remains unencrypted. Data is stored exclusively in ISO 27001 certified German data centers. Third-party sharing is limited to payment processors. The policy is transparent and references specific GDPR legal bases. Areas of concern include the campaign analysis feature that hashes IP addresses and user agents with campaign IDs under legitimate interest rather than consent, and the policy's silence on AI/model training. Law enforcement disclosure is possible under court order, though encrypted content would be inaccessible to Tuta.
Category Assessment
Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.
End-to-end encryption of all user data, no cookies, only essential metadata stored unencrypted, and IP addresses stored only in anonymized form.
Policy clearly specifies each data category collected, its purpose, legal basis under GDPR, and retention periods with specific article references.
Data shared only with payment processors (credit institutions, PayPal) and law enforcement under court order; explicit statement that no data is sold.
All data stored in ISO 27001 certified data centers in Germany with no mention of any transfers outside the EU/EEA.
Policy is completely silent on AI or model training; while Tuta's encryption model makes unauthorized use unlikely, explicit confirmation is absent.
Comprehensive listing of GDPR rights (Articles 15-20, 21, 77) including access, rectification, erasure, restriction, portability, objection, and complaint to supervisory authority.
Key Findings
Notable clauses, issues, or positive practices discovered (critical first)
Campaign analysis processes hashed identifiers under legitimate interest without explicit consent
The policy states that when users arrive via campaign links, Tuta stores a cryptographic hash of IP address and user agent together with a campaign ID linked to the Tuta account. This is processed under Art. 6(1)(f) legitimate interest rather than consent. While the hash is claimed to prevent re-identification, the combination of hash + campaign ID + account linkage means Tuta can associate campaign attribution with specific users for 30 days. This is a form of tracking that relies on legitimate interest balancing rather than user consent.
Law enforcement disclosure clause could compel inventory and traffic data
The policy states: 'we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies.' While end-to-end encryption protects content from Tuta's own access, inventory data (email address, name, billing address) and traffic data (metadata such as sender/recipient addresses and timestamps) could be disclosed. Users should understand that metadata is not end-to-end encrypted and is accessible to Tuta and thus to authorities.
Email metadata is stored unencrypted and accessible to Tuta
The policy explicitly states: 'Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.' This means that while email content is protected by end-to-end encryption, the social graph of who communicates with whom and when is visible to Tuta and could be disclosed under court order. Mail server logs containing sender/recipient addresses and connection times are retained for up to 7 days.
No cookies and no third-party analytics tools used
The policy explicitly states 'We do not use cookies' and 'we do not use analysis tools such as Google Analytics or other third-party tools.' Usage statistics are opt-in, anonymized, and self-hosted. This is a notably strong anti-tracking stance that eliminates common web surveillance vectors.
Data retention after account termination has exceptions that could extend storage significantly
While the default is deletion within 30 days of contract termination, the policy lists multiple exceptions: accounting data may be retained until fee disputes are resolved, inventory data can be stored for up to two years for complaint handling, and deletion may be omitted where legal regulations or prosecution of claims require it. Tax, contract, and commercial law retention periods also apply to order-related data. These exceptions could result in some personal data persisting well beyond the 30-day baseline.
Consumer Takeaway
Tuta is one of the strongest privacy-oriented email services available, with genuine end-to-end encryption that even Tuta itself cannot bypass, though users should be aware that email metadata and campaign tracking data are not encrypted.
Compliance Posture
Tuta demonstrates strong GDPR compliance with a German-based controller, appointed DPO, clear legal bases for each processing activity, and comprehensive data subject rights documentation.
EU Transfers
No international transfers. All data is stored exclusively in ISO 27001 certified data centers in Germany, within the EU/EEA.
Detected Signals
Specific data points and practices identified in the text
Evidence Snippets
Direct quotes from the policy supporting these findings
All user data is stored end-to-end encrypted in Tuta. Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.
We do not use cookies.
In order to evaluate campaigns with partners and advertising campaigns...we store a cryptographic hash of connection data like the IP address and the user agent...together with the campaign ID when you visit our website via a campaign link.
The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case.
However, we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies. There will be no sale of data.
Missing or Unclear
- Explicit statement on whether user data is used for AI or model training
- Details on data portability implementation (how to export data in machine-readable format)
- Specific retention periods for each data category beyond the general 30-day post-termination rule
- Whether campaign analysis can be opted out of
- Details on sub-processors beyond payment providers
- Whether Tuta has received law enforcement requests and published transparency reports
Questions to Ask
- How does Tuta implement the right to data portability (Art. 20 GDPR) for end-to-end encrypted data — can users export their encrypted and unencrypted data in a structured, machine-readable format?
- Can users opt out of campaign analysis tracking, or is the legitimate interest balancing the only recourse via the right to object under Art. 21 GDPR?
- Has Tuta published a transparency report detailing the number and types of law enforcement requests received and how they were responded to?
- What specific anonymization technique is used for IP addresses, and has Tuta assessed whether the combination of anonymized IP, device type, and geolocation could lead to re-identification?
- Does Tuta use any user data (including metadata or anonymized usage statistics) for training machine learning models or AI systems?
- What happens to the campaign analysis hash and campaign ID data if a user deletes their account during the 30-day retention window?
Share this analysis
Anyone with this link can view the result above.
Built by DentroChat
100% European AI chat for everyone
Chat with AI, work with files, generate images, and search the web. Data stays in Europe.
Other analysed privacy policies
View allgdprchat.eu
88/100
Low privacy riskGDPRchat offers exceptionally strong EU-centric privacy with no tracking and self-service data controls, but users should be aware that image prompts may be used for AI training by a third-party provider.
View report →proton.me
88/100
Low privacy riskProton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.
View report →kolsetu.com
85/100
Low privacy riskKolsetu generally respects EU privacy rules, but it over‑collects usage data, lacks a public DPO, and provides limited detail on some international transfers.
View report →startpage.com
90/100
Low privacy riskStartpage offers exceptional privacy by design, collecting virtually no personal data and explicitly rejecting tracking, profiling, and search logging, though minor data flows to third-party ad and analytics providers exist.
View report →